
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23760 is an authentication bypass vulnerability in the password reset API of SmarterTools SmarterMail, allowing unauthenticated attackers to reset system administrator account passwords and achieve full administrative compromise. The vulnerability was discovered by watchTowr Labs researchers Piotr Bazydlo and Sina Kheirkhah on January 8, 2026, reported to the vendor, patched on January 15, 2026 (build 9511), and publicly disclosed on January 22, 2026. All SmarterMail versions prior to build 9511 (version 100.0.9511) are affected. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (watchTowr Labs, CISA KEV).
The root cause is CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The vulnerable endpoint POST /api/v1/auth/force-reset-password is decorated with AllowAnonymous = true, permitting unauthenticated access. When the attacker-controlled IsSysAdmin field is set to true, the code path for resetting a system administrator password executes without verifying the OldPassword field or any reset token — despite the API accepting these fields. The regular user password reset path correctly validates the existing password, but the privileged administrator path does not. An attacker only needs to supply a valid administrator username (commonly admin or administrator) and a chosen new password in a JSON POST request to take over the account. Once admin access is obtained, SmarterMail's built-in Volume Mounts feature under Settings allows arbitrary OS command execution, escalating the auth bypass to full SYSTEM/root-level RCE (watchTowr Labs, Huntress).
Successful exploitation grants an unauthenticated attacker full administrative control over the SmarterMail instance, with high impact on confidentiality, integrity, and availability. Because SmarterMail system administrator privileges include the ability to execute OS commands via built-in management functionality, attackers effectively gain SYSTEM (Windows) or root (Linux) access on the underlying host. Real-world impacts have included ransomware deployment (WarLock and Medusa), data exfiltration, lateral movement across networks, and in at least one documented case, the vendor SmarterTools itself was breached through an unpatched instance of its own software (watchTowr Labs, Huntress, ReliaQuest).
This vulnerability is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on January 26, 2026, with a remediation due date of February 16, 2026. Exploitation was observed as early as January 17, 2026 — just two days after the patch was released — indicating attackers performed patch diffing to reconstruct the vulnerability. Multiple public PoC exploits are available, including on GitHub (MaxMnMl PoC) and a second PoC (hilwa24 PoC). The EPSS score is approximately 0.499 (49.9%), reflecting high exploitation probability. Threat actors Storm-2603 (deploying WarLock ransomware) and Storm-1175 (a China-linked group deploying Medusa ransomware, often within 24 hours of vulnerability disclosure) have been attributed to exploitation campaigns. Shadowserver identified over 6,000 internet-exposed SmarterMail servers likely vulnerable at the time of disclosure (CISA KEV, Huntress, Microsoft Security Blog, ReliaQuest).
admin or administrator; the API returns USER_NOT_FOUND for invalid usernames, enabling enumeration./api/v1/auth/force-reset-password with the following JSON payload, setting IsSysAdmin to true:POST /api/v1/auth/force-reset-password HTTP/1.1
Host: <target>:9998
Content-Type: application/json
{"IsSysAdmin":"true", "OldPassword":"anything", "Username":"admin", "NewPassword":"Attacker123!@#", "ConfirmPassword": "Attacker123!@#"}A successful response returns "success":true with resultCode:200.
4. Authenticate as admin: POST to /api/v1/auth/authenticate-user with the newly set credentials to obtain a valid session token.
5. Achieve RCE via System Events: Use the admin session to POST to /api/v1/settings/sysadmin/event-hook to create a malicious system event containing an OS command payload. Trigger the event by adding a domain via /api/v1/settings/sysadmin/domain-put, causing the command to execute at SYSTEM/root level.
6. Cover tracks: Delete the malicious event hook and added domain via /api/v1/settings/sysadmin/event-hook-delete and /api/v1/settings/sysadmin/domain-delete/ to remove indicators of compromise.
7. Establish persistence/deploy payload: Drop ransomware, establish a reverse shell, or exfiltrate data from the now-compromised host (watchTowr Labs, Huntress).
/api/v1/auth/force-reset-password from external/unexpected IP addresses; observed attacker IP ranges include 142.111.152[.]x and 155.2.215[.]x subnets; User-Agent string python-requests/2.32.4 associated with automated exploitation tooling./api/v1/auth/force-reset-password, /api/v1/auth/authenticate-user, /api/v1/settings/sysadmin/event-hook, /api/v1/settings/sysadmin/domain-put, /api/v1/settings/sysadmin/domain-delete/, and /api/v1/settings/sysadmin/event-hook-delete in rapid succession; audit log entries for force-reset-password from unauthenticated or unexpected sources.C:\Program Files (x86)\SmarterTools\SmarterMail\Service\wwwroot\result.txt containing reconnaissance command output; unexpected files dropped in the SmarterMail web root or service directories.cmd.exe, powershell.exe, bash) executing reconnaissance or payload delivery commands.The primary remediation is to upgrade SmarterMail to build 9511 or later, released January 15, 2026, which adds ValidatePassword verification to the system administrator password reset path. No vendor-provided workaround exists for unpatched systems; organizations unable to patch immediately should restrict network access to the SmarterMail API port (default 9998) and web interface to trusted IP ranges only, and monitor for suspicious POST requests to the /api/v1/auth/force-reset-password endpoint. CISA's BOD 22-01 requires federal agencies to remediate this vulnerability by February 16, 2026. Given active ransomware exploitation, patching should be treated as an emergency priority (SmarterTools Release Notes, CISA KEV, watchTowr Labs).
The watchTowr Labs team (Piotr Bazydlo and Sina Kheirkhah) published a detailed technical write-up on January 22, 2026, noting that attackers appeared to have used decompilers to reverse-engineer the patch and reconstruct the vulnerability within days of its release — a technique they described as rare and alarming. Huntress independently observed and documented in-the-wild exploitation, publishing their own analysis the same day. The Shadowserver Foundation scanned the internet and reported over 6,000 exposed SmarterMail servers likely vulnerable, generating significant community concern on Reddit and security forums. The vulnerability attracted widespread media coverage from BleepingComputer, The Hacker News, SecurityWeek, and SC World, particularly after the WarLock ransomware group (Storm-2603) breached SmarterTools' own network using an unpatched instance of their own software — an irony widely noted in the security community. Microsoft's April 2026 threat intelligence blog further elevated awareness by linking Storm-1175 (a China-linked group) to exploitation of this CVE in Medusa ransomware operations, often deploying ransomware within 24 hours of gaining access (watchTowr Labs, Huntress, Microsoft Security Blog, ReliaQuest).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."